NarraSEO
Features About Pricing FAQ Affiliate
Try Narra free
Try Narra free
Mori Digital Group LLC

Privacy Policy

How Mori Digital Group LLC collects, uses, and shares information when you use NarraSEO.

Last updated August 27, 2026

Document version 2026.08.27

Privacy Terms Cookies DPA Affiliates Referrals

Contents

Who we are What we collect What we do not collect Publicly accessible data Internal access Legal bases AI processing Google Limited Use Subprocessors Customer-directed transfers Security Retention Where data is processed Your rights (GDPR and UK GDPR) Your rights (California CPRA) International transfers Cookies Marketing email Children Changes Contact

01Who we are#

NarraSEO is operated by Mori Digital Group LLC ("we", "us", or "NarraSEO"), a New York limited liability company. The Service is directed primarily at customers in the United States. Our notice address is:

Mori Digital Group LLC
418 Broadway STE 11054
Albany, NY 12207
support@narraseo.com
privacy@narraseo.com

For account, billing, and workspace administration data, we act as a controller. For content, prompts, documents, and other materials you submit so we can provide the Service, we act as a processor on your instructions. Our Data Processing Addendum describes processor terms for business customers.

Mori Digital Group LLC has not appointed an EU or UK Article 27 representative. If we expand marketing or sales into the EU or UK in a way that requires a representative, we will update this Privacy Policy with the representative's contact details.

02What we collect#

We collect only what we need to run NarraSEO, bill for it, and keep it secure:

Identity and account

  • Name, email address, password credentials or OAuth identifiers, and profile settings.
  • Workspace and team membership, roles, invitations, and seat assignments.
  • Authentication session data needed to keep you signed in.

Workspace and product content

  • Documents, drafts, outlines, research notes, brand profiles, writing styles, and related project metadata.
  • Chat messages and inputs for AI-assisted features you use.
  • Uploaded files and attachments within product limits.
  • Derived indexes used so search and chat features can find relevant material in your workspace.

Integrations

  • Connection metadata for platforms you authorize (for example Search Console, Analytics, or a CMS).
  • OAuth tokens and related secrets stored with encryption, separate from ordinary connection records.
  • Synced performance and property data needed to power the connected features you enable.

Billing and usage

  • Subscription status, plan, invoices, and payment references held by our payment processor. We do not store full card numbers.
  • Credit grants, reservations, ledger events, and feature usage records used to meter paid work.
  • Checkout intent and plan selection needed to complete purchase flows.

Support and operations

  • Messages you send to support, and diagnostic logs needed to investigate incidents.
  • Security and abuse-prevention signals processed by our infrastructure providers.

03What we do not collect#

We do not store payment card numbers, CVV codes, or full bank account numbers. Our payment processor handles card data on our behalf.

NarraSEO's own application records do not store your IP address or user agent for ordinary product use. Infrastructure providers that host and deliver the Service (including hosting, analytics, and error monitoring) may process IP addresses and related network metadata as part of normal security, delivery, measurement, and diagnostics.

04Publicly accessible data#

Some product surfaces make content reachable without signing in. You should treat them as public until you revoke access.

  • Account images. Profile images, brand logos, and similar media you upload for the product may be served from public URLs.
  • Private attachments. Attachments for private AI workflows are stored privately and are not publicly listed.
  • Share links. Features that let you create a share link publish a sanitized snapshot to anyone who has the URL. You can revoke those links. Until revoked, treat the snapshot as public.

05Internal access#

Access inside Mori Digital Group LLC is limited to people who need it for support, security, billing, or operations.

  • Billing and account administration. Narrow, multi-factor-protected access to account and billing records. It does not include read access to your documents, chats, or connected Search Console / Analytics datasets.
  • Operational access. Privileged credentials used for support, security response, billing investigation, migrations, and background jobs, limited to personnel who need them for those tasks.

06Legal bases#

Where the GDPR or UK GDPR applies, we rely on these bases:

  • Contract. Creating and managing your account, delivering the Service, metering credits, and processing billing.
  • Legitimate interests. Securing the platform, preventing abuse, improving reliability, and measuring aggregated site and product usage (including via Google Analytics where enabled), balanced against your rights.
  • Consent. Optional marketing email where required, and other processing where we ask for consent.
  • Legal obligation. Tax, accounting, and responding to lawful requests.

07AI processing#

When you use AI-assisted features, relevant prompts, documents, attachments (within product limits), and related context are sent to third-party AI providers so we can generate outputs.

We do not use your content to train our own models, and we do not fine-tune third-party models on your data. Operational usage records may include account, feature, and metering metadata, not raw prompts for training.

AI providers process that data as subprocessors under their terms and our instructions. See Subprocessors below.

08Google Limited Use#

If you connect Google Search Console or Google Analytics, we request limited OAuth scopes needed for those features. Refresh tokens are stored securely.

We use Google user data only to provide user-facing Search Console and Analytics features inside NarraSEO. We do not sell Google user data. We do not use it for advertising. We do not send your GSC or Analytics datasets to AI providers for generation.

Some optional product actions may open a tool in your own browser that you choose to use. Those actions are initiated by you and are not a server-side transfer of your Google datasets to an AI provider.

Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

09Subprocessors#

We use the subprocessors below. Status reflects the committed production configuration and may change as we operate the Service.

Vendor Purpose Status
SupabaseDatabase, authentication, storage, vault secretsAlways active
StripePayments, subscriptions, customer portalAlways active
VercelApplication hosting and edge deliveryAlways active
ResendAccount, billing, and lifecycle emailAlways active
AnthropicAI generation and chat workloadsActive when configured
OpenAIAI generation, embeddings, and image generationActive when configured
Google GeminiAI generation workloadsActive when configured
PerplexityResearch and retrieval-assisted generationActive when configured
xAIAI generation workloadsActive when configured
DataForSEOKeyword and SERP research dataActive when configured
FirecrawlSite crawling and page extractionActive when configured
TavilyWeb research retrievalActive when configured
PageSpeed InsightsPage performance signalsActive when configured
YouTube Data APIVideo metadata for supported workflowsActive when configured
PexelsStock imageryActive when configured
UnsplashStock imageryActive when configured
Google OAuth APIsGSC and GA connections you authorizeActive when you connect
Shopify, Wix, BigCommerceCommerce publishing OAuth when configuredActive when configured
Cloudflare TurnstileBot protection on auth surfacesAlways active
ReditusAffiliate attributionActive when enabled
SentryError monitoringActive when enabled
Google AnalyticsSite and product usage analyticsActive when enabled

We will update this list when the subprocessors that process personal data for the Service change. Business customers under the DPA receive change notice as described there.

10Customer-directed transfers#

You can instruct NarraSEO to send content to systems you control. Examples include publishing to your CMS (such as WordPress, Webflow, Duda, or Ghost) with credentials you provide, delivering webhooks to your endpoints, and exposing REST or RSS feeds you enable. Those transfers are directed by you. The receiving systems are your processors or controllers, not ours, once delivery leaves NarraSEO.

11Security#

We apply technical and organizational measures appropriate to a multi-tenant SaaS product, including access controls, encrypted secrets, TLS for ordinary web and API traffic, and optional multi-factor authentication (required for privileged internal access).

No method of transmission or storage is perfectly secure. You are responsible for protecting account credentials and for reviewing outputs before you publish them.

12Retention#

We retain personal data only as long as needed for the purposes described here. Operational windows include:

  • Account deletion. After you request deletion, a 14-day grace period runs, then primary account data is purged. Encrypted backups age out on a separate cycle.
  • Credits. Plan credits expire at period end (with a short grace). Purchased packs remain valid for a limited period from grant as described in product billing terms.
  • Credit Activity and ledger metering. Credit Activity in the product shows the last 90 days. Credit ledger metering records are retained for 365 days, then removed by automated cleanup. That schedule does not change Stripe invoices or payment records.
  • Temporary holds and uploads. Stale credit holds and unlinked temporary uploads are cleaned on a short schedule.
  • Invitations and notifications. Invitations expire after a short period. In-app notifications are retained briefly.
  • Connected analytics sync logs. Operational sync logs are retained for a limited period and then removed.
Credit Activity in the product UI is a 90-day visibility window. It is not the deletion schedule for ledger metering records (365 days). Performance views in the product UI are a 90-day window on every plan. That is not a deletion schedule. Performance and analytics data associated with an account is retained for the life of the account unless the account is deleted or law requires removal.

13Where data is processed#

Primary application data for NarraSEO is processed in the United States. Subprocessors that host, deliver, or power AI features may also process data where they operate. International transfer safeguards are described below and in the DPA.

14Your rights (GDPR and UK GDPR)#

If the GDPR or UK GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is consent-based. You may also lodge a complaint with a supervisory authority.

To exercise these rights, email privacy@narraseo.com. We aim to respond within 30 days.

15Your rights (California CPRA)#

If you are a California resident, the CPRA provides rights to know, delete, correct, and limit use of sensitive personal information, and to non-discrimination for exercising those rights. Authorized agents may submit requests as permitted by law.

We do not sell personal information and we do not share personal information for cross-context behavioral advertising as those terms are defined under the CPRA.

Categories we collect are described in "What we collect" above. Categories we disclose to service providers and contractors are limited to what is needed for the subprocessors and customer-directed transfers listed in this policy.

Submit CPRA requests to privacy@narraseo.com. We aim to respond within 45 days, or longer where the law allows an extension.

16International transfers#

If we transfer personal data from the EEA, UK, or Switzerland to countries that do not provide an adequacy decision, we rely on appropriate safeguards such as the European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum, as described in our DPA.

17Cookies#

We use cookies and similar technologies needed to authenticate you, remember preferences, complete checkout, and (when enabled) measure site and product usage with Google Analytics and affiliate attribution. Details are in our Cookie Policy.

18Marketing email#

We may send product and marketing email where permitted. Transactional messages about your account, security, billing, and the Service are not marketing. You can unsubscribe from marketing messages using the link in those emails or by contacting support. We honor unsubscribe requests for marketing mail.

19Children#

NarraSEO is for users who are 18 years of age or older. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

20Changes#

We may update this Privacy Policy from time to time. The version string and "Last updated" date at the top will change when we do. Material changes will be highlighted in-product or by email when appropriate. Continued use of the Service after an update means you acknowledge the revised policy.

21Contact#

Privacy questions and data subject requests: privacy@narraseo.com. Account and billing support: support@narraseo.com.

Postal notice address:

Mori Digital Group LLC
418 Broadway STE 11054
Albany, NY 12207

NarraSEO

One workspace to research, write, publish, repurpose, and measure content that earns search and AI traffic.

Product

Features Pricing FAQs

Pages

Home About

Resources

Documentation Privacy Policy Terms of Service Cookie Policy DPA Affiliate Terms Referral Terms Media kit Support

Ask AI about NarraSEO

Copyright © 2026. A product of Mori Digital Group LLC.

System Status
Try Narra free